Senior Cyber Security Engineer @OnTrac
All Others
Salary usd 156,000 - 2..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted YDay

[Hiring] Senior Cyber Security Engineer @OnTrac

YDay - OnTrac is hiring a remote Senior Cyber Security Engineer. πŸ’Έ Salary: usd 156,000 - 234,000 per year πŸ“Location: USA

Role Description

OnTrac is hiring a Sr Cyber Security Engineer (PAM / IAM)! Are you eager to join a dynamic and expanding company where you can both learn and make a meaningful impact? If you possess a strong sense of empathy, enjoy assisting others, thrive in a fast-paced environment, and excel at problem-solving, we encourage you to apply today to connect with a recruiter!

The Sr. Cyber Security Engineer is a senior-level individual contributor and hands-on technical owner for Identity and Access Management (IAM), Privileged Access Management (PAM), Entra ID, Microsoft 365, vulnerability management, and mobile device management. This broad security engineering role requires deep identity expertise alongside the ability to support endpoint, cloud, and SaaS security. The Engineer partners daily with IT to secure infrastructure and end-user services, enables the Cyber Security Incident Response Team (CSIRT) as a Tier 3 escalation point, and supports Governance, Risk, and Compliance (GRC) by translating control requirements into technical configurations and automated evidence collection.

Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field, or equivalent practical experience
  • 7+ years of progressive experience in IT and Security, including at least 3 years dedicated to IAM or security engineering in an enterprise environment
  • Demonstrated hands-on ownership of at least two of the following:
    • Entra ID / Microsoft 365
    • A PAM platform
    • Qualys or equivalent vulnerability management platform
    • Intune / JAMF device management
  • Hands-on expertise with identity lifecycle, RBAC design, entitlement and access certification, federation and SSO integrations, and privileged-access tooling and workflows
  • Strong working knowledge of Entra ID, including Conditional Access, Identity Protection, PIM, and entitlement management, plus the Microsoft 365 security and compliance stack
  • Working knowledge of Intune, JAMF, and Google device management, including compliance policies, configuration profiles, and application deployment across mixed operating-system environments
  • Strong scripting and automation skills using PowerShell, Microsoft Graph, Python, or Bash
  • Ability to interpret NIST CSF, ISO 27001, or SOC 2 and implement the technical controls and evidence required to meet them
  • Certifications such as SC-300, SC-200, AZ-500, CISSP, CISM, GIAC GCIA, GIAC GDSA, or relevant PAM, JAMF, or Qualys vendor certifications
  • Ability to travel up to 10%

Requirements

  • Identity and privileged-access engineering:
    • Design, deploy, and maintain enterprise identity services across Entra ID and hybrid Active Directory, including SAML/OIDC federation, SSO, Conditional Access, MFA and phishing-resistant authentication, joiner/mover/leaver automation, RBAC, role and group governance, access reviews, credential vaulting, session monitoring, just-in-time elevation, tiered administration, service-account governance, and break-glass procedures.
  • Microsoft 365 and Entra ID security:
    • Harden and administer Exchange Online, SharePoint, OneDrive, Teams, Defender, Purview, and the Entra ID tenant, including configuration baselines, application registration and OAuth consent governance, license-aligned feature enablement, and posture remediation.
  • Vulnerability, endpoint and mobile security:
    • Operate Qualys, including asset coverage, tagging, authenticated scanning, agents, policy compliance, and risk-based reporting; drive remediation within established SLAs; and manage compliance, configuration, enrollment, encryption, patching, application deployment, and device-posture signals across Intune, JAMF, and Google device management for Windows, macOS, iOS, and Android.
  • IT partnership and security by design:
    • Serve as the embedded security engineering partner for directory, endpoint, network, and infrastructure changes, applying security by design to projects, migrations, and new deployments without unnecessarily slowing delivery.
  • CSIRT enablement and Tier 3 escalation:
    • Support complex identity and endpoint incidents through containment actions, including token revocation, account disablement, and device isolation; assist with evidence collection, log-source onboarding, and detection tuning in partnership with CSIRT and the MDR provider.
  • GRC enablement and technical controls:
    • Translate requirements from NIST CSF, ISO 27001, and SOC 2 into technical configurations and automated evidence collection that supports audits, third-party risk reviews, and risk-remediation tracking.
  • Automation, documentation and mentorship:
    • Automate recurring identity, access, integration, and reporting tasks using PowerShell, Microsoft Graph, and Python; maintain runbooks, SOPs, architecture diagrams, and platform standards; and provide technical guidance to analysts and junior engineers.

Benefits

  • Medical, dental, and vision insurance
  • Life and short- and long-term disability coverage
  • 401(k) retirement savings plan with company match
  • Flex vacation in states other than CA, CO, IL, MA, MT, and NE, with accruals up to 96 hours for first year of employment with tenure-based increases up to 160 hours
  • Two (2) floating holidays per year
  • Paid sick leave*
  • Six (6) paid company holidays
  • Two (2) weeks paid pregnancy disability leave, four (4) weeks paid parental bonding leave
  • Additional wellness and employee assistance programs
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Cyber Security Engineer @OnTrac
All Others
Salary usd 156,000 - 2..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted YDay
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 128,512+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later